Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Spotify

Security Engineer – Detection and Response

Spotify

. Identify detection opportunities and define telemetry requirements .

Posted 9/24/2026full-timeNew York City • New York • United StatesMid-LevelSenior💰 $132,948 - $189,927 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in security operations, incident response, and threat detection, with a strong focus on developing and tuning detection mechanisms across various environments. Proficient in creating AI workflows and utilizing automation to enhance investigation processes and improve security outcomes.

Highest-signal resume keywords
Security OperationsIncident ResponseDetection EngineeringSIEM, EDR, SOARPython Programming

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Threat DetectionDetection TuningAlert TriageInvestigation WorkflowsAI Workflow CreationDetection-as-Code PracticesCloud Platform ExperienceAutomation Platform UsageTelemetry AnalysisSecurity Judgment
Soft Skills
Clear DocumentationCollaborative CommunicationInclusive Teamwork
Tools & Technologies
SIEMEDRSOARGitHubCI/CDGoogle CloudAWSAzure
Industry Keywords
Threat IntelligenceSecurity FindingsSaaS SecurityIncident ContainmentProactive Threat Identification

Tech Stack

Tools & technologies
AWSAzureCloudPython

About the role

Key responsibilities & impact
  • Identify detection opportunities and define telemetry requirements
  • Partner with the detection infrastructure squad and data owners to make detection and investigation signals available
  • Develop, test, tune, and maintain detections across endpoint, identity, cloud, SaaS, email, and other security-relevant environments
  • Investigate and prioritize alerts, determine security impact, and participate in incident containment and remediation
  • Build repeatable investigation workflows and playbooks for alert triage, evidence collection, decision-making, escalation, containment, and response
  • Improve proactive threat identification and threat hunting using internal telemetry and external threat intelligence
  • Create AI workflows for Detection and Response that enrich alerts, analyze evidence, guide investigations, and automate repetitive response work
  • Measure detection effectiveness, identify coverage gaps, and tune detections to balance security value, fidelity, and analyst workload
  • Use SIEM, EDR, SOAR, and related security platforms to research threats, develop detections, investigate alerts, and validate security outcomes
  • Share knowledge, document decisions, and communicate security findings to technical and non-technical audiences
  • Partner with detection infrastructure and teams across Spotify to support detection and response at scale

Requirements

What you’ll need
  • 3+ years of hands-on experience in security operations, incident response, threat detection, detection engineering, or closely related work
  • Understanding of analyst alert triage and investigation workflows
  • Experience creating and tuning detections based on attacker behavior, available telemetry, and expected investigation paths
  • Experience with SIEM, EDR, SOAR, or comparable monitoring and response technologies
  • Ability to write code or use an automation platform to analyze security telemetry, enrich alerts, build investigation workflows, and remove repetitive work
  • Experience with Python or a similar language is valuable
  • Understanding of detection-as-code practices, including GitHub, peer review, CI/CD, testing, and safely managing production detection content
  • Experience with at least one major cloud platform, such as Google Cloud, AWS, or Azure
  • Understanding of common threats affecting SaaS-oriented corporate and production environments
  • Ability to document clearly, collaborate inclusively, and explain security concepts to people with different backgrounds and expertise
  • Ability to create and critically evaluate AI workflows for detection development, alert triage, security investigations, and response
  • Appropriate security judgment and human oversight

Benefits

Comp & perks
  • Equity
  • Health insurance
  • Six-month paid parental leave
  • 401(k) retirement plan
  • Monthly meal allowance
  • 23 paid days off
  • Paid flexible holidays
  • Paid sick leave
  • Flexible work from home
  • Reasonable accommodations during the interview process